A computer-implemented system and method for pool-based identity authentication for service access without use of stored credentials is disclosed. The method in an example embodiment includes providing provisioning information for storage in a provisioning repository; receiving a service request from a service consumer, the service request including requestor identifying information; generating an authentication request to send to an authentication authority, the authentication request including requestor identifying information; receiving validation of an authenticated service request from the authentication authority; and providing the requested service to the service consumer.
Legal claims defining the scope of protection, as filed with the USPTO.
1. A method comprising: receiving, at an authentication authority, an authentication request from a web service provider, the authentication request comprising a service request by a service requestor to the web service provider to access a web service, and a service requestor identifying information; determining authentication information from the service request sent to the web service, the service request comprising the authentication information; validating the authentication information using independently verifiable data; and in response to validating the authentication information meets the independently verifiable data, sending a grant or denial of access to the web service.
2. The method of claim 1 , wherein the authentication information comprises an IP address of the service request and the independently verifiable data comprises a range of IP addresses.
3. The method of claim 2 , wherein the IP address of the service request is extracted from an x-Forwarded HTTP value.
4. The method of claim 1 , wherein the authentication information comprises content of the service request.
5. The method of claim 1 , wherein the authentication information includes an attribute of the service request.
6. The method of claim 1 , further comprising performing a test on the independently verifiable data.
7. The method of claim 1 , further comprising retrieving the independently verifiable data from a secure provisioning repository.
8. A system comprising: a memory device for storing instructions; and a processor, which, when executing the instructions, causes the system to perform operations comprising: receiving an authentication request from a web service provider, the authentication request comprising a service request by a service requestor to the web service provider to access a web service, and a service requestor identifying information; determining authentication information from the service request sent to the web service, the service request comprising the authentication information; validating the authentication information using independently verifiable data; and in response to validating the authentication information meets the independently verifiable data, sending a grant or denial of access to the web service.
9. The system of claim 8 , wherein the authentication information comprises an IP address of the service request and the independently verifiable data comprises a range of IP addresses.
10. The system of claim 9 , wherein the IP address of the service request is extracted from an x-Forwarded HTTP value.
11. The system of claim 8 , wherein the authentication information comprises content of the service request.
12. The system of claim 8 , wherein the authentication information includes an attribute of the service request.
13. The system of claim 8 , wherein the operations further comprise performing a test on the independently verifiable data.
14. The system of claim 8 , wherein the operations further comprise retrieving the independently verifiable data from a secure provisioning repository.
15. A computer readable non-transitory storage medium storing at least one program configured for execution by a computer, the at least one program comprising instructions to perform operations comprising: receiving an authentication request from a web service provider, the authentication request comprising a service request by a service requestor to the web service provider to access a web service, and a service requestor identifying information; determining authentication information from the service request sent to the web service, the service request comprising the authentication information; validating the authentication information using independently verifiable data; and in response to validating the authentication information meets the independently verifiable data, sending a grant or denial of access to the web service.
16. The computer readable non-transitory storage medium of claim 15 , wherein the authentication information comprises an IP address of the service request and the independently verifiable data comprises a range of IP addresses.
17. The computer readable non-transitory storage medium of claim 16 , wherein the IP address of the service request is extracted from an x-Forwarded HTTP value.
18. The computer readable non-transitory storage medium of claim 15 , wherein the authentication information comprises content of the service request.
19. The computer readable non-transitory storage medium of claim 15 , wherein the authentication information includes an attribute of the service request.
20. The computer readable non-transitory storage medium of claim 15 , wherein the operations further comprise performing a test on the independently verifiable data.
Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.
September 6, 2018
October 1, 2019
Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.